Malicious PDF — malware analysis report

Static analysis result for SHA-256 4ec931fdf328958a…

MALICIOUS

PDF

98.0 KB Created: 2020-04-11 14:01:22 +03:00 Authoring application: wkhtmltopdf 0.12.1.4 (via Qt 4.8.6)
MD5: d0b8d5c00da80330f313aeee6eea196d SHA-1: 21deebcd06e2e00b277eca687c59bc7828233318 SHA-256: 4ec931fdf328958a81b272d28f99fa01ac5f21e59273266bc834263e1b34fec5
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file contains a mass of external links, many of which point to other PDF files hosted on similar domains, suggesting a link farm designed to distribute malicious content. The ML classifier strongly indicated maliciousness, and the presence of numerous external URIs points towards a delivery mechanism for further payloads or phishing content. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://saranlpcoach.com/uploads/1/3/0/3/130323453/130323453.html#templates+powerpoint+%C4%91%E1%BA%B9p
    • http://shuyukan.ch/uploads/1/3/0/7/130775056/fotukavaru_fasukumisupubuk_foxofibamojura.pdf
    • http://caryleeflowers.com/uploads/1/3/0/9/130969536/6836110.pdf
    • http://edgedesigngroupinc.com/uploads/1/3/0/6/130604524/sabodur_mugirumu_buwexawolobanib.pdf
    • http://utilidrone.fr/uploads/1/3/1/0/131069763/1d0e2e3053b.pdf
    • http://maribethvanderweele.com/uploads/1/3/1/3/131384618/gelisarabo-wedonutat-kezov-sazobefotigaj.pdf
    • http://sheriprice.com/uploads/1/3/0/2/130289430/6e046ae23f251.pdf
    • http://toner4you.net/uploads/1/3/1/4/131408528/puxumadat_tufoz.pdf
    • http://bambooandroses.org/uploads/1/3/0/8/130814110/retigurufutaj-mufenidofu.pdf
    • http://riverofnoreturnidaho.com/uploads/1/3/0/2/130291785/vovawavudu.pdf
    • http://garytigner.com/uploads/1/3/0/4/130476185/882217.pdf
    • http://justfortonight.org/uploads/1/3/0/8/130874521/mobonemetuta.pdf
    • http://clearlakelionshop.com/uploads/1/3/0/5/130589320/4803616.pdf
    • http://amaceying.com/uploads/1/3/0/6/130639051/d05d72570c1616.pdf
    • http://washingtonstateapples.com/uploads/1/3/1/4/131407005/tipebola.pdf
    • http://carnivalincovington.org/uploads/1/3/0/9/130969266/jukopexugibe_zigixelomuwek.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00012c62.bin
9b6ec4f1ca39306d58821fbe2c5094ea8a2f64e0ce4f1858195cd1b31cd964e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x12C62 11092 bytes
font_01_sfnt_off00014eaf.bin
27aad4e7100ae85831cc1a9cf4859e84521ff6b1ee9ac199fa10e6c4d4b25dad
pdf-font-stream PDF embedded font (sfnt) at offset 0x14EAF 2736 bytes
font_02_sfnt_off0001585c.bin
3197f84515da5a689d4eeb7abd1e574b7ea7ed86583edd3617a89f89e6dcb29d
pdf-font-stream PDF embedded font (sfnt) at offset 0x1585C 24836 bytes